Authentication Bypass in Creativeitem Academy LMS by Predictable JWT Token Signing
CVE-2025-56749
9.4CRITICAL
What is CVE-2025-56749?
Creativeitem Academy LMS versions up to and including 6.14 contain a vulnerability due to the use of a hardcoded default JWT secret for token signing. This predictable secret compromises the integrity of token-based authentication, allowing malicious actors to forge valid JWT tokens. Consequently, attackers can bypass authentication mechanisms, gaining unauthorized access to user accounts and sensitive information within the platform.
